Whats wrong with the way Windows Media Player 9 Series provides access to the Media Library?
The Windows Media Player 9 Series ActiveX control uses the Windows Media Player public object model, and provides access to the media library under certain conditions. The Windows Media Player 9 Series ActiveX control is a scriptable component, meaning that script code can be used to invoke or control it. The ActiveX control does not properly validate requests made by script to access the Media Library. What are ActiveX controls? ActiveX is a technology that allows Web authors the ability to embed small programs in Web pages or other interfaces to provide additional functionality. These embedded programs are known as ActiveX Controls. Developers can create ActiveX controls in any programming language that supports the Microsoft Common Object Model. I have my Windows Media Player 9 Series configured to not run script automatically. Does this protect me from this vulnerability? No – in this case it is the ActiveX control running the script code that allows access to the Media Library, no